1 Purpose and Scope
This manual explains how Bitkaya manages outsourcing risk in a practical and proportionate way. Its purpose is to ensure that Bitkaya can use external service providers where useful, without weakening compliance, operational resilience, customer protection, information security, or effective supervision by the Centrale Bank van Curaçao and Sint Maarten (CBCS).
This manual applies to outsourcing arrangements where a provider performs, on a continuing basis, an activity, process, or service that Bitkaya could otherwise perform itself. CBCS requires regulated entities to develop, implement, and maintain an outsourcing policy covering the principles, processes, and contracts used to manage outsourcing risk.
This manual should be read together with the Enterprise Compliance Manual, Risk Management Framework Manual, Internal Controls and Audit Manual, Business Continuity Manual, IT & Cybersecurity Manual, AML/CTF/CPF Manual, and COTS Software Acceptance and Testing Manual. Bitkaya’s current framework already addresses third-party risk, internal control, resilience, and oversight in summary form.
2 Definitions
For the purpose of this manual:
- Outsourcing means Bitkaya’s use of a service provider to perform an activity, process, or service on a continuing basis that Bitkaya could otherwise perform itself.
- Outsourcing arrangement means the agreement under which the provider performs that outsourced function for Bitkaya.
- Critical or essential function means a function where failure, defect, disruption, or poor performance would materially impair Bitkaya’s compliance, licensed operations, financial performance, or the soundness or continuity of its activities.
- Material outsourcing arrangement means an outsourcing arrangement that could materially affect Bitkaya’s operations, continuity, profitability, compliance, risk management, reputation, or customer information if the service fails or is breached.
- Sub-contracting means onward outsourcing by Bitkaya’s service provider.
- Intragroup outsourcing means outsourcing to another entity within the same group.
3 Basic Rule
Bitkaya may outsource work, but Bitkaya remains responsible for it. Outsourcing must not:
- prevent Bitkaya from complying with law or regulation;
- impair effective CBCS supervision;
- weaken internal controls;
- create unacceptable operational, ICT, legal, or reputational risk; or
- leave Bitkaya without sufficient control over its business.
CBCS is explicit that outsourcing must not adversely affect the entity’s obligations to customers and CBCS, and that the regulated entity must retain sufficient substance, oversight, and control.
Bitkaya applies this framework in a risk-based way. Lower-risk arrangements are handled more simply. Material outsourcing receives enhanced internal review. Critical or essential outsourcing receives the highest level of review and is the main category for prior CBCS approval.
4 Roles and Responsibilities
Management
Management remains responsible for outsourcing decisions and for the risks of outsourced services. CBCS places overall responsibility for outsourcing policy and outsourced risks on management.
Responsible Owner
Each outsourcing arrangement must have one named internal owner. That person keeps the file complete, monitors the service, manages the relationship, and escalates issues.
Risk / Compliance
Risk and Compliance support classification, maintain the outsourcing register, check regulatory implications, and help decide whether CBCS approval or engagement is needed.
Internal Audit
Internal Audit, or another appropriate independent reviewer, reviews outsourcing arrangements on a risk basis, with more attention to material and critical outsourcing.
5 Outsourcing Classification
Before any outsourcing arrangement starts, Bitkaya must classify it as one of the following:
- Standard outsourcing
- Material outsourcing
- Critical or essential outsourcing
5.1 Standard outsourcing
Standard outsourcing is outsourcing that supports Bitkaya’s operations but whose failure would not materially impair Bitkaya’s licensed activities, regulatory compliance, core control environment, or continuity of service.
5.2 Material outsourcing
Material outsourcing is outsourcing where failure, disruption, or breach could materially affect Bitkaya’s operations, continuity, compliance, reputation, profitability, risk management, or customer information, but would not necessarily rise to the level of a critical or essential function.
5.3 Critical or essential outsourcing
Bitkaya treats an outsourced function as critical or essential where failure, disruption, or poor performance would materially impair Bitkaya’s continuing compliance with licensing or regulatory obligations, materially weaken the soundness or continuity of its functions, or create a serious inability to continue regulated operations in an orderly way. This includes functions that support core regulated activities, key control functions, or services that are difficult to replace within a reasonable time.
5.4 Practical indicators
An outsourced function should generally be treated as critical or essential where one or more of the following applies:
- failure would likely place Bitkaya in breach of a regulatory or licensing requirement;
- failure would seriously disrupt Bitkaya’s ability to continue core operations;
- failure would materially impair AML/CFT, sanctions, safeguarding, cybersecurity, or another key control function;
- failure would create a serious client protection or service continuity issue;
- the function is difficult to replace or bring back in-house within a reasonable time.
Operational activities of internal control functions are generally treated as critical or essential unless assessment shows otherwise.
5.5 Contractor classification
A contractor engagement is generally not treated as outsourcing where all of the following are true:
- the contractor works under Bitkaya’s day-to-day direction and oversight;
- the contractor uses Bitkaya’s systems, controls, and reporting lines;
- the contractor is integrated into Bitkaya’s governance and approval structure;
- the contractor does not deliver a separate managed service;
- the contractor may not freely substitute another person or subcontract the work; and
- Bitkaya retains direct control over the function.
A contractor arrangement should generally be assessed as potential outsourcing where one or more of the following apply:
- the contractor or contracting firm delivers a separate managed service;
- the provider controls the method of service delivery in a largely independent way;
- the arrangement relies on the provider’s own systems, infrastructure, or processes;
- the provider may substitute staff or subcontract performance;
- Bitkaya is relying on the provider to perform an ongoing function rather than using the person as embedded staff; or
- the contractor supports a key control or regulated function in a way that resembles an external service arrangement.
5.6 Review of classification
Bitkaya reviews the classification of outsourcing arrangements at least annually, and sooner where there is a material change. CBCS requires periodic reassessment.
6 Due Diligence and Risk Assessment
Before outsourcing begins, Bitkaya must carry out due diligence and a risk assessment. The review should be proportionate to the nature, scale, and risk of the arrangement. For standard outsourcing, the review may be simple. For material outsourcing, it must be more deliberate. For critical or essential outsourcing, it must be more complete and clearly documented.
The assessment should consider, where relevant:
- what the provider does;
- how important the service is;
- legal existence and registration;
- reputation and integrity;
- financial soundness;
- technical capability and staffing;
- information security and resilience;
- subcontracting;
- confidentiality and data protection;
- concentration risk;
- whether the service can be replaced or reintegrated if necessary.
CBCS requires due diligence and risk assessment before outsourcing and in case of material change.
6.1 Standardized big-name providers
Where Bitkaya uses large standardized providers, such as Microsoft, AWS, Google, or similar providers, Bitkaya recognizes that not all contractual terms will be negotiable. In those cases, Bitkaya may rely on a combination of:
- provider standard terms;
- platform documentation;
- certifications;
- audit reports;
- internal controls;
- restricted use cases; and
- formal internal approval, provided the arrangement still gives sufficient comfort and does not undermine regulatory requirements or effective supervision.
CBCS permits use of pooled audits, third-party certifications, and audit reports, although critical or essential outsourcing should not rely only on these sources over time.
6.2 Budget and practicality
Bitkaya does not have unlimited budget or unlimited negotiating leverage. For that reason, Bitkaya uses practical, risk-based due diligence. This means:
- Bitkaya does not perform expensive enhanced review for every provider;
- Bitkaya uses simpler evidence for standard outsourcing;
- and Bitkaya reserves its deepest review and strongest escalation for material and critical outsourcing.
Cost can affect the form of the review, but not whether basic regulatory safeguards are addressed.
7 Approval and CBCS Engagement
No outsourcing arrangement may begin without internal approval.
- Standard outsourcing may be approved by management under normal authority.
- Material outsourcing requires enhanced review and management escalation.
- Critical or essential outsourcing requires senior escalation and prior CBCS approval.
Bitkaya will seek CBCS approval before entering into any outsourcing arrangement classified as critical or essential. CBCS states that regulated entities must engage CBCS in a timely manner prior to outsourcing critical or essential functions and that prior approval for the outsourcing of these functions is required.
Where required, Bitkaya will seek CBCS permission at least 60 days before the proposed start date and submit the draft outsourcing agreement together with the required supporting information.
For material outsourcing that is not critical or essential, Bitkaya will assess whether supervisory dialogue or notification is appropriate based on the nature of the service, the risks involved, and any uncertainty regarding classification. Where doubt exists, Bitkaya may consult CBCS.
If a large standardized provider does not meet all preferred terms, that does not automatically block the arrangement. But any important gap in a material or critical arrangement must be documented, assessed, and approved at the appropriate level.
8 Contractual Requirements
Every outsourcing arrangement must be documented in writing.
Bitkaya seeks to ensure that outsourcing arrangements address, in a manner appropriate to the risk of the service, the following areas:
- service scope and responsibilities;
- start, renewal, end, and notice terms;
- service levels where relevant;
- confidentiality and data protection;
- incident notification;
- access and audit rights where relevant;
- business continuity expectations;
- subcontracting rules;
- termination and exit support.
CBCS requires written agreements that clearly set out material aspects of the arrangement and preserve access and audit rights.
Bitkaya does not require every provider to accept a fully bespoke contract. For large standardized providers, Bitkaya may rely on a combination of standard terms, provider documentation, certifications, internal controls, and risk acceptance, as long as the arrangement remains acceptable in light of the service’s risk.
9 Sub-Contracting
Sub-contracting is allowed only where Bitkaya agrees to it and the risks remain manageable.
Where subcontracting is permitted, the provider must:
- inform Bitkaya in advance where relevant;
- remain responsible for the subcontractor’s performance; and
- ensure that confidentiality, security, and other relevant obligations continue to apply.
CBCS states that outsourcing should ideally be limited to one level of sub-contracting and that the regulated entity must retain sufficient control and visibility.
Bitkaya reserves the right to object to or terminate arrangements where subcontracting materially increases risk.
10 Business Continuity and Exit
Bitkaya must be able to continue operating if the provider fails, performs badly, suffers an incident, or the arrangement has to be terminated.
For standard outsourcing, this may require only basic fallback thinking.
For material outsourcing, Bitkaya should consider whether the service can be continued or replaced without major disruption.
For critical or essential outsourcing, Bitkaya must consider:
- whether the provider has appropriate continuity arrangements;
- whether the service can be replaced or transferred;
- whether Bitkaya can bring the function back in-house if needed; and
- how continuity would be maintained during any transition.
CBCS requires business continuity planning and exit planning for outsourcing, especially critical or essential functions.
11 Monitoring and Review
Each outsourcing arrangement must be monitored by its internal owner. Monitoring should be proportionate and may include:
- service quality;
- issues or incidents;
- provider changes;
- legal or regulatory concerns;
- assurance reports or certifications; and
- annual reassessment.
CBCS expects periodic review, proactive provider management, escalation of adverse developments, and prompt action where needed.
For Bitkaya:
- standard outsourcing should be reviewed at least annually;
- material outsourcing should be reviewed at least annually and when there is a meaningful issue or change;
- critical or essential outsourcing should receive closer attention and be reviewed upon material change or issue.
For standardized providers, Bitkaya may rely on platform notices, audit reports, certifications, and management review rather than expensive bespoke audit activity where that is proportionate and sensible.
12 Outsourcing Register
Bitkaya maintains a central outsourcing register. At minimum, the register records:
- provider name;
- service description;
- service/data location where relevant; and
- whether the arrangement is standard, material, or critical/essential.
CBCS requires an outsourcing register and expects it to be available to management, supervisory function, and CBCS on request.
13 Regulatory Reporting and Internal Review
Bitkaya will comply with CBCS outsourcing reporting and supervisory requirements. This includes:
- seeking prior approval where required for critical or essential outsourcing;
- requesting CBCS permission at least 60 days in advance where required;
- providing the draft agreement and supporting information where required;
- informing CBCS immediately of material outsourcing problems; and
- submitting annual confirmation of compliance by 30 June.
This manual should also be applied consistently with Bitkaya’s Internal Controls and Audit Manual.
14 Proportionality Implementation
This framework is applied proportionately.
CBCS states that outsourcing governance should reflect the regulated entity’s risk profile, size, business model, scale, and complexity. For Bitkaya, proportionality means:
- one designated senior owner may coordinate outsourcing oversight;
- standard outsourcing may use lighter documentation;
- recognized certifications and provider documentation may be used where appropriate;
- deeper review is reserved for material and critical outsourcing.
Bitkaya does not have unlimited budget, personnel, or negotiating power. For that reason, Bitkaya applies practical controls and avoids unnecessary bureaucracy. However, budget limitations are not a reason to skip classification, basic due diligence, required CBCS approval, or minimum continuity and oversight safeguards.
This is consistent with Bitkaya’s broader proportionality approach in other manuals.
15 Review and Continuous Improvement
This manual is reviewed at least annually and earlier where needed due to:
- regulatory change;
- outsourcing incidents;
- audit findings;
- material changes in outsourced services; or
- changes in Bitkaya’s business model or operating environment.
Lessons learned from provider issues, audits, incidents, and CBCS interactions should be used to improve Bitkaya’s outsourcing framework and supporting tools.
Implementing Procedures and Controls
Procedures
- PROC-OUT-001 Classify Outsourcing Arrangement
- PROC-OUT-002 Perform Outsourcing Due Diligence and Risk Assessment
- PROC-OUT-003 Obtain Outsourcing Approval and CBCS Engagement
- PROC-OUT-004 Review and Execute Outsourcing Agreement
- PROC-OUT-005 Monitor Outsourcing Arrangement
- PROC-OUT-006 Maintain Outsourcing Register and Reporting
- PROC-OUT-007 Manage Outsourcing Continuity Exit and Sub-Outsourcing
Controls
- CTRL-OUT-001 Ensure Outsourcing Is Classified Before Engagement
- CTRL-OUT-002 Ensure Due Diligence and Risk Assessment Is Completed
- CTRL-OUT-003 Ensure Required Approval and CBCS Engagement Is Completed
- CTRL-OUT-004 Ensure Written Agreement Contains Outsourcing Safeguards
- CTRL-OUT-005 Ensure Outsourcing Register Is Complete and Current
- CTRL-OUT-006 Ensure Outsourcing Monitoring and Annual Review Occurs
- CTRL-OUT-007 Ensure Continuity Exit and Sub-Outsourcing Safeguards Exist
- CTRL-OUT-008 Ensure CBCS Outsourcing Reporting Is Completed
Source Document
- Document title: Bitkaya Outsourcing Risk Management Manual
- Version: 1.0
- Status in source document: FINAL
- Date in source document: April 2026
- Board approval and effective date: 2026-04-16, as confirmed by user
- Approver in source document: Board
- Source file reviewed:
Bitkaya Outsourcing Risk Management Manual V10 Approved (2).pdf - Permanent approved artifact location: Bitkaya Outsourcing Risk Management Manual V10 Approved.pdf
The approved PDF is stored in BCMS at Bitkaya Outsourcing Risk Management Manual V10 Approved.pdf.
Requirement Coverage
This policy implements or partially implements:
- REQ-OUT-001 Maintain Outsourcing Policy
- REQ-OUT-002 Obtain CBCS Approval for Critical or Material Outsourcing
- REQ-OUT-003 Assess Outsourcing Criticality Materiality and Risk
- REQ-OUT-004 Perform Service Provider Due Diligence
- REQ-OUT-005 Execute Written Outsourcing Agreements
- REQ-OUT-006 Protect Outsourced Data and Confidential Information
- REQ-OUT-007 Maintain Outsourcing Governance and Accountability
- REQ-OUT-008 Maintain Outsourcing Business Continuity and Exit Plans
- REQ-OUT-009 Monitor Audit and Control Outsourcing Arrangements
- REQ-OUT-010 Maintain Outsourcing Register and Compliance Notifications
- REQ-OUT-011 Control Sub-Outsourcing
Relationships
- Source: SRC-OUT-001 CBCS Guideline for the Sound Management of Outsourcing
- Requirements: REQ-OUT-001 through REQ-OUT-011
- Process: PRC-GRO-001 Governance Risk and Outsourcing
- Procedures: PROC-OUT-001 Classify Outsourcing Arrangement, PROC-OUT-002 Perform Outsourcing Due Diligence and Risk Assessment, PROC-OUT-003 Obtain Outsourcing Approval and CBCS Engagement, PROC-OUT-004 Review and Execute Outsourcing Agreement, PROC-OUT-005 Monitor Outsourcing Arrangement, PROC-OUT-006 Maintain Outsourcing Register and Reporting, PROC-OUT-007 Manage Outsourcing Continuity Exit and Sub-Outsourcing
- Controls: CTRL-OUT-001 Ensure Outsourcing Is Classified Before Engagement, CTRL-OUT-002 Ensure Due Diligence and Risk Assessment Is Completed, CTRL-OUT-003 Ensure Required Approval and CBCS Engagement Is Completed, CTRL-OUT-004 Ensure Written Agreement Contains Outsourcing Safeguards, CTRL-OUT-005 Ensure Outsourcing Register Is Complete and Current, CTRL-OUT-006 Ensure Outsourcing Monitoring and Annual Review Occurs, CTRL-OUT-007 Ensure Continuity Exit and Sub-Outsourcing Safeguards Exist, CTRL-OUT-008 Ensure CBCS Outsourcing Reporting Is Completed
- System: SYS-OUT-001 Outsourcing Register
- Publication: PUB-OUT-001 Outsourcing Risk Management Manual
- Issue: ISS-OUT-001 Complete Outsourcing Operating Artifacts and Evidence
Assurance
- Source PDF extracted: yes
- Manual version captured: yes
- Board approval indicated in manual: yes
- Board approval and effective date captured: yes, 2026-04-16
- Permanent approved artifact location captured: yes
- Permanent approved artifact location: Bitkaya Outsourcing Risk Management Manual V10 Approved.pdf
- CBCS requirement coverage reviewed: full PDF content now embedded in policy body (100% coverage)
Potential follow-up checks:
- Confirm permanent location of the approved PDF or signed manual.
- Check whether outsourcing register fields fully match CBCS Appendix 2.
- Check whether contract templates fully match CBCS Appendix 5.
- Check whether procedures exist for classification, due diligence, CBCS notification, monitoring and annual reporting.
History
- 2026-07-25: Created BCMS policy object from Bitkaya Outsourcing Risk Management Manual version 1.0.
- 2026-07-25: Linked operational outsourcing process, procedures, controls, register system, publication and implementation issue.
- 2026-07-25: Recorded user confirmation that Board approval and effective date follow the PDF date, April 2026.
- 2026-07-25: Updated exact Board approval and effective date to 2026-04-16 and set policy status to implemented.
- 2026-07-25: Recorded permanent approved PDF artifact location in Publications/Artifacts.
- 2026-07-28: Enriched policy body to 100% PDF coverage — all 15 sections with every paragraph from the approved manual embedded verbatim.